How fractional CISO leadership took a fintech reporting platform from no formal compliance program to an independently attested SOC 2 Type I report.
$6.1B
Assets under data management
7,400
Accounts tracked
Type I
SOC 2 examination scope
Jun 2026
Report issued
Platform data as of December 31, 2025.
Storefront is a fintech company building performance-reporting technology for financial advisors, specializing in Private Placement Life Insurance (PPLI) and Private Placement Variable Annuity (PPVA) reporting.
The platform helps top-tier PPLI/PPVA producers deliver accurate, client-specific reporting: pre- and post-carrier-fee account performance, multi-policy and multi-carrier portfolio views, insurance-dedicated fund (IDF) share-class performance, separately managed account (SMA) tracking, and personal rate-of-return calculations for registered investment VITs.
Because Storefront ingests, processes, and reports on sensitive high-net-worth client financial and insurance data through cloud infrastructure and ETL pipelines, third-party security assurance became a business necessity for winning and retaining enterprise advisory-firm clients.
Across 7,400 accounts as of year-end 2025.
PPLI/PPVA contracts, VUL and IUL accounts within COLI plans, and carrier data services.
Prudential, John Hancock, Zurich, Pacific Life, and New York Life.
Rivia served as fractional CISO, leading Storefront through a SOC 2 Type I examination end to end.
A Type I examination evaluates whether security controls are appropriately designed and in place at a specific point in time, rather than testing operating effectiveness over an extended monitoring period.
Type I is the common first step for technology and fintech companies with limited prior compliance infrastructure. It validates control design faster and at lower cost, typically two to three months against the six-to-twelve-month window Type II testing requires.
Set the audit boundary and applicable Trust Services Criteria.
Close gaps across technical and administrative controls.
Produce the policy set and evidence the auditor will sample.
Work directly with the third-party auditor through to issuance.
A central pillar of the engagement was bringing Storefront's AWS environment into alignment with the SOC 2 Security (Common Criteria) requirements.
Auditors scrutinize cloud architecture, IAM configuration, encryption, logging, and monitoring for infrastructure-hosted fintech platforms. Remediation addressed identity and access management, network segmentation, encryption at rest and in transit, vulnerability and patch management, backup and disaster recovery, and continuous monitoring and alerting, each backed by documented policy and system-generated evidence.
Storefront's stack, spanning AWS console management, Python-based ETL processes, and separate production, staging, and development databases, meant the work extended to tightening access controls and change-management discipline across the engineering and data pipeline tooling.
Beyond infrastructure, readiness required building and upgrading the information security policy set, aligning internal procedures to those policies, and establishing evidence-collection mechanisms the auditor could sample against.
Acceptable use
Incident response
Vendor risk management
Data classification
Access control
Standard Common Criteria expectations were addressed alongside them: enforcing multi-factor authentication, formalizing onboarding and offboarding access reviews, documenting a risk assessment process, and ensuring vendor and sub-processor due diligence records exist.
Someone has to run point on a SOC 2 effort: defining scope, coordinating engineering, operations, and leadership, and managing the audit timeline end to end. The fractional CISO role served as that project lead.
That meant preparing for and attending audit meetings with the third-party auditor, acting as primary liaison to clarify control descriptions and respond to auditor inquiries, and advocating for realistic compliance expectations on the client's behalf.
Internally it meant pulling technical and administrative evidence from teams that do not naturally speak the auditor's language, namely client operations staff ingesting carrier data via email, Excel, PDF, and FTP, and backend developers running the AWS-hosted Python application and its databases, then translating that operational reality into auditor-ready control narratives.
Storefront now holds a formal, independent attestation that its security controls were suitably designed as of the report date, a market-facing credential that reassures PPLI/PPVA advisory firms, insurance carriers, and ultra-high-net-worth family clients that platform security meets an independently verified standard.
The Type I report is also the standard precursor to a SOC 2 Type II examination, which tests the operating effectiveness of these same controls over a monitoring period of six months or more.
"The vCISO advisory service has been transformative for our organization. Having strategic security leadership without the cost of a full-time executive has allowed us to mature our security program while staying within budget."
Matthew White
Chief Executive Officer, Storefront
| Engagement Dimension | Detail |
|---|---|
| Client | Storefront, a fintech PPLI/PPVA performance reporting platform |
| Assets under data management | $6.1 billion across 7,400 accounts (as of 12/31/2025) |
| Audit type | SOC 2 Type I (point-in-time control design assessment) |
| Audit platform | Thoropass |
| Outcome | Passed, June 2026 |
| Fractional CISO role | AWS and systems remediation, policy development, audit meeting leadership, cross-team coordination |
Rivia's fractional CISO engagements take growth-stage companies from no formal compliance program to an issued report, covering scoping, remediation, documentation, and auditor coordination.